Vybe applies the GDPR data-subject rights to every user, regardless of location. Privacy isn't a regional checkbox — we built the same consent + export + deletion machinery for every market we operate in.
Your rights (and how to exercise them)
Right to access (Art. 15)
Open Settings → Privacy → Export my data. You'll get a JSON download with everything we hold about you — account, numbers, call metadata, voicemail transcripts, settings — within 24 hours.
Right to rectification (Art. 16)
Edit your profile information at any time from Settings → Account. For corrections to system records (call metadata, billing), email privacy@vybe.app.
Right to erasure (Art. 17)
Open Settings → Account → Delete account. We'll:
- Sign you out everywhere and revoke push tokens immediately.
- Soft-delete your account so it's invisible to other users.
- Hard-delete all your data within 30 days (the grace period gives us time to recover from accidental requests).
- Email you confirmation when deletion is complete.
Some metadata (anonymised call records for regulatory compliance) may be retained for up to 7 years — but stripped of all linking identifiers.
Right to data portability (Art. 20)
The export from Right to access above is in standard JSON format suitable for importing into other compliant services.
Right to object (Art. 21)
You can object to processing based on legitimate interest at any time by emailing privacy@vybe.app.
Right to restrict processing (Art. 18)
You can ask us to pause processing while we investigate a complaint by emailing privacy@vybe.app.
Right to withdraw consent (Art. 7(3))
Any consent you gave (marketing emails, analytics opt-in, etc.) can be withdrawn anytime from Settings → Privacy.
Lawful bases for processing
- Contract (Art. 6(1)(b)) — provisioning numbers, routing calls/SMS, billing.
- Legitimate interest (Art. 6(1)(f)) — fraud prevention, abuse detection, security.
- Legal obligation (Art. 6(1)(c)) — emergency services compliance, tax records.
- Consent (Art. 6(1)(a)) — marketing, optional analytics, optional product features.
Third-party processors
We use Tier-1 service providers across a small number of categories — telecom interconnection, push notifications, cloud hosting, encrypted storage, crash reporting, product analytics and transactional email. All providers are bound by a written Data Processing Agreement and (where relevant) EU Standard Contractual Clauses.
A current named list of sub-processors is available on request at privacy@vybe.app. We respond within 7 days, and update the list at least 30 days before adding any new sub-processor that materially changes data flow.
Data Protection Officer
Megmaa Solutions Pvt. Ltd. has appointed a Data Protection Officer for all GDPR matters.
DPO: dpo@vybe.app
EU Representative (Art. 27): eu-rep@vybe.app
Right to complain
If you believe your rights have been violated, you can lodge a complaint with your local supervisory authority. A list is maintained at the EDPB website.
Data breach notification
In the unlikely event of a data breach, we'll notify the relevant supervisory authority within 72 hours as required by Art. 33, and affected users individually if there's a high risk to their rights.